82% on the first official practice assessment — 41 of 50, weakest in Domain 2 (Architecture & Services). Nine questions missed, and they split into two kinds: a scenario-recognition pattern that showed up twice (Conditional Access), and a handful of facts genuinely never covered in Lessons 1–16. This lesson patches both before a retake.
Missed twice, same root cause both times: a scenario described a sign-in restricted by device compliance or which client app is being used, and MFA or RBAC got picked instead of Conditional Access.
| Signal in the scenario | Feature |
|---|---|
| "Only allowed from a compliant/managed device" | Conditional Access |
| "Only allowed from an approved client app" | Conditional Access |
| "Prompted for a code or fingerprint at sign-in" | MFA |
| "Granted permission to manage resources in a group" | RBAC |
The tell: Conditional Access questions describe a condition being evaluated (device, location, app, risk) that gates access. MFA questions describe an extra proof of identity. RBAC questions describe what someone's allowed to do, not whether they can sign in at all.
Not covered in Lesson 6 — a genuine gap, not a recall miss. A service endpoint extends a virtual network's identity to a specific Azure PaaS service (like Azure SQL Database or Storage), over the Azure backbone, so that service can be restricted to accept traffic only from that VNet's subnet.
NSG — firewall rules (allow/deny) filtering traffic in and out, at a subnet or NIC. Service endpoint — restricts a PaaS service to accept traffic only from a specific VNet subnet. Private endpoint (Lesson 6) — gives a PaaS resource a private IP inside the VNet itself. Peering (Lesson 6) — connects two VNets directly. If a question asks "connect a VNet to an Azure SQL/Storage resource," NSG is never the answer — it only filters traffic, it doesn't create connectivity.
Azure Files (Lesson 7) is accessible over SMB and NFS — not FTP, which Azure Files doesn't support at all.
Lesson 3 covered IaaS/PaaS/SaaS responsibility boundaries but not billing. SaaS is typically licensed through a flat monthly or annual subscription — one price regardless of exact usage. IaaS and PaaS stay consumption-based (Lesson 1) — pay for what you actually use. Microsoft 365 (subscription) vs. a pay-as-you-go VM (consumption) is the contrast to anchor this on.
"What's created inside a subscription?" → resource groups and resources. A management group sits above subscriptions in the hierarchy (Lesson 4) — it's not something a subscription contains, it's something a subscription can belong to.
Lesson 14 paired Policy against RBAC; add a third contrast. Azure Policy — enforces compliance, can block or flag non-compliant resources automatically, mandatory. Azure Advisor (Lesson 16) — surfaces optional recommendations you choose whether to act on. "Ensure resources stay in compliance with corporate standards" is Policy's job, not Advisor's — Advisor never blocks anything.